The Audit Defense Library

Practitioner-depth analysis across federal and private compliance: FISMA and NIST RMF, FedRAMP, CMMC, federal AI governance, SOC 2, AI governance, cybersecurity, and GRC engineering. Written by a CPA, CISSP, CISA with Big 4 audit experience.

All FISMA & NIST RMF FedRAMP CMMC Federal AI Governance GovCon Compliance Federal Cybersecurity Federal Zero Trust Federal GRC Engineering AI Governance GRC Engineering Cybersecurity Cloud Security HIPAA SOC 2
HIPAA

HIPAA Risk Assessment: Five-Step Process for OCR

Every HIPAA risk assessment I review commits the same fundamental error. The document is titled "Risk Assessment." The content is a checklist. MFA: yes. Encryption: yes. Backup: yes. A series of binary answers telling OCR...

Read the Guide
AI Governance

What Counts as PHI in AI Tools? The 2026 “Mosaic Effect” Guide

In 2000, Latanya Sweeney at Carnegie Mellon demonstrated that 87% of the U.S. population becomes uniquely identifiable from three data points: five-digit ZIP code, gender, and date of birth [Sweeney 2000]. She proved it by...

Read the Guide
AI Governance

What Is AI Governance? The 2026 Strategic Guide

Three regulatory frameworks converge in 2026 to create the first global standard for governing artificial intelligence. The EU AI Act enters general application August 2, 2026, when GPAI model obligations and most operational provisions become...

Read the Guide
HIPAA

BAA for Google Drive

The most common HIPAA violation I encounter during healthcare practice assessments is the one nobody suspects. Not missing encryption. Not absent multi-factor authentication (MFA). A therapist, office manager, or billing coordinator sending patient intake forms...

Read the Guide
HIPAA

Do I Need a Firewall for HIPAA? (Router vs. Firewall Guide 2026)

In April 2012, a small cardiology practice in Phoenix paid $100,000 to settle an Office for Civil Rights (OCR) enforcement action targeting network security infrastructure. Phoenix Cardiac Surgery, a five-physician group, was cited for lacking...

Read the Guide
Cybersecurity

Vulnerability Scanning vs Penetration Testing Explained

When was the last time a human attacker tested whether your vulnerability scan findings are actually exploitable? Not a scanner running automated checks against a database. A certified ethical hacker chaining vulnerabilities together, testing business...

Read the Guide
HIPAA

Is ChatGPT HIPAA Compliant? Plan-by-Plan Matrix

Which ChatGPT plan does your organization use? Not the plan the IT department approved. The plan your clinical staff actually uses. The one a medical assistant discovered through a colleague. The one a billing specialist...

Read the Guide
HIPAA

What Is a Business Associate Agreement (BAA)?

Before the 2013 HIPAA Omnibus Rule, Business Associates operated in a regulatory gray zone. Covered entities signed agreements. Vendors accepted them. HHS had no direct enforcement authority over the vendors themselves. When Advocate Medical Group...

Read the Guide
Cybersecurity

NIST CSF 2.0 Implementation: The C-Suite Investment Guide

When ISO 27001 introduced Annex A revisions in 2022, organizations that had built their programs on the original control set spent months remapping evidence. The frameworks did not change materially. The structure changed. Control numbering...

Read the Guide
SOC 2

SOC 2 Incident Response Checklist: 8 Evidence Items

Most compliance teams treat incident response evidence as a documentation exercise: write the plan, run the annual tabletop, file the sign-in sheet. SOC 2 auditors evaluate incident response under three distinct criteria: CC7.2 (detection), CC7.3...

Read the Guide
Cybersecurity

Vulnerability Scanning Frequency: Asset-Based Schedule

Eighty-nine days. The average window between quarterly vulnerability scans where new threats go undetected. During those 89 days, automated scanning tools probe every internet-facing IP address continuously [Verizon 2024 DBIR]. CISA adds entries to its...

Read the Guide
Cybersecurity

What is Vulnerability Management? 5-Step Lifecycle

In 2003, the SQL Slammer worm exploited a vulnerability Microsoft had patched six months earlier. The worm infected tens of thousands of servers in minutes. The organizations breached had scanning tools and access to the...

Read the Guide
The Authority Brief

One compliance analysis per week from Josef Kamara, CPA, CISSP, CISA. Federal and private compliance, written for practitioners.